PT-2023-24775 · Twig+1 · Twig+1

Scgajge12

·

Published

2023-06-14

·

Updated

2023-06-22

·

CVE-2023-34251

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Grav versions prior to 1.7.42
Description The issue allows for server-side template injection, which can lead to remote code execution. This can be achieved by embedding malicious PHP code on the administrator screen by a user with page editing privileges. The vulnerability exploits the system function in the Twig template engine, allowing an attacker to execute arbitrary system commands.
Recommendations For Grav versions prior to 1.7.42, update to version 1.7.42 or later to resolve the issue. As a temporary workaround, consider restricting access to the administrator screen and the edit functionality for users with page editing privileges until the update can be applied.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-34251
GHSA-F9JF-4CP4-4FQ5

Affected Products

Grav
Twig